Threat reportPhishingTL-2026-3037

RMM tools distributed via phishing: ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud and N-able abused for remote access

highACTIVE

RMM tools distributed via phishing (TL-2026-3037) is a high-severity phishing campaign, first published 2026-10-01. It has no confirmed attribution, affects ConnectWise ScreenConnect (abused, not vulnerable), maps to 11 MITRE ATT&CK techniques (T1036.005, T1036.008, T1059.003), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-3037

Threat ID
TL-2026-3037
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, legal, enterprise, managed-service-providers
Target regions
Global, North America
Detection rules
9
Indicators of compromise
28

Malware and tooling in RMM tools distributed via phishing

Malware and tooling: BlackCat (Windows), BlackCat - S1068, MEDUSA - S1220, PLAY Ransomware, ConnectWise - S0591, FleetDeck.io, Jump Cloud, ScreenConnect, SimpleHelp

How RMM tools distributed via phishing works

AhnLab ASEC reports ongoing phishing campaigns, first seen in January 2026, that deliver legitimate Remote Monitoring and Management (RMM) agents (ScreenConnect, FleetDeck, Datto RMM, SimpleHelp, JumpCloud, N-able) to victims. Because the binaries are legitimately signed tools without malware signatures, they evade traditional detection while giving operators interactive remote access.

AhnLab Security Intelligence Center (ASEC) published on 2026-10-01 an analysis of phishing campaigns that distribute six legitimate RMM products instead of custom malware. The activity was first detected in January 2026 and is ongoing. The tools are real vendor software configured with attacker-controlled tenant, server or account identifiers, so the endpoint shows a signed, trusted agent beaconing to an attacker-controlled instance.

Delivery varies by tool. ScreenConnect is delivered through LNK, BAT and VBS email attachments with deceptive names (Dropbox.SharedfilePDF.LNK, ZoomSetup-V.7.3.Bat, Wire Receipt Form_pdf.Vbs); the C2 server and port are embedded in the installer execution arguments, and ScreenConnect.ClientSetup.msi was fetched from attacker hosts such as 216.250.252.58:8040 and admin.lukiku.lol (relay.lukiku.lol observed as relay). FleetDeck is delivered through PDF documents with clickable links that download an installer; a deployment ID appended to the end of the file is passed as the -deploymentID argument (fleetdeck_agent_svc.exe -deploymentID <uuid> -askForName=0). ASEC associates FleetDeck use with Scattered Spider, which previously distributed DragonForce ransomware. Datto RMM is delivered through PDFs showing a fake Adobe Acrobat Pro update prompt that downloads AdrAcroPro11.2_3D_client.Exe; the CagService.Exe.Config file holds an AccountUid that identifies the operator. SimpleHelp is delivered through HTML phishing scripts, with the C2 server address stored hex-encoded in the sg_servers configuration entry; ASEC notes SimpleHelp abuse in Play, Medusa and ALPHV (BlackCat) intrusions. JumpCloud is delivered through phishing pages impersonating Adobe security documents; batch malware downloads and runs the agent with the operator's CONNECT_KEY argument. N-able is delivered through batch malware disguised as DocuSign Viewer that shows a fake DocuSign page while installing the agent; its settings.Ini contains the operator email mark@hessattorneys.co.za.

Corroborating public reporting shows the same technique class at scale: ANY.RUN research (published 2026-08-25) tracked 425 phishing-kit URLs across 240 hosts between 5 February and 29 July 2026 in 46 countries (about 45% US), with 94% of hosts live for a single day, and lures impersonating tax agencies, Social Security, Adobe, invoices, shipping and DocuSign. Red Canary and Zscaler (2025-09-12) documented ITarian, PDQ, SimpleHelp and Atera delivered via fake browser updates, fake Teams/Zoom/Excel updates, e-invite lures and government-form lures, with dual-RMM redundancy (SimpleHelp followed by ScreenConnect) and follow-on payloads such as HijackLoader and DeerStealer. Netlas (2026-06-05) lists MuddyWater, Hive affiliates, Storm-1811 and RansomHub as RMM abusers. No CVE is involved; the risk is abuse of legitimate functionality, so detection must rely on allow-listing approved RMM products and tenant IDs, and on behavioral telemetry (unexpected RMM installs, LNK/BAT/VBS launching installers, msiexec fetching from non-vendor hosts).

MITRE ATT&CK techniques used in TL-2026-3037

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1036.008 Masquerade File Type

Execution

T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204.001 Malicious Link; T1204.002 Malicious File

Command and Control

T1219.002 Remote Desktop Software

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1608.001 Upload Malware

Affected products and versions in RMM tools distributed via phishing

  • ConnectWise — ScreenConnect (abused, not vulnerable)
  • FleetDeck — FleetDeck Agent (abused, not vulnerable)
  • Datto (Kaseya) — Datto RMM (abused, not vulnerable)
  • SimpleHelp — SimpleHelp (abused, not vulnerable)
  • JumpCloud — JumpCloud Agent (abused, not vulnerable)
  • N-able — N-able RMM (abused, not vulnerable)
  • Microsoft — Windows (target platform)

Remediation for RMM tools distributed via phishing

Immediate actions

  • Block the listed domains, IP addresses and URLs at proxy, DNS and email gateways
  • Hunt endpoints for ScreenConnect, FleetDeck, Datto RMM, SimpleHelp, JumpCloud and N-able agents that are not in the approved RMM inventory
  • Quarantine email attachments of type LNK, BAT, VBS and HTML with document-themed names (Dropbox, Zoom, Wire Receipt, DocuSign, Adobe)
  • Isolate hosts where an unapproved RMM agent was installed and rotate credentials used on them

Workarounds

  • Block egress to unapproved RMM relay infrastructure
  • Verify sender trust and inspect intermediate redirects in linked URLs before opening

Longer-term hardening

  • Maintain an allow-list of sanctioned RMM products and tenant/instance/account identifiers, and alert on any other
  • Use application control (WDAC/AppLocker) to block unapproved remote-access software
  • Restrict script-host and LNK execution from user-writable and mail-attachment paths
  • Train users that software-update prompts inside PDFs and fake Adobe/DocuSign pages are phishing

Timeline of RMM tools distributed via phishing

  • AhnLab ASEC reports the first detection of the RMM-via-phishing campaigns in January 2026; activity continues through the report date
  • ANY.RUN's tracking window of RMM phishing-kit URLs begins (425 URLs across 240 hosts through 2026-07-29, 46 countries, ~45% US)
  • Netlas publishes Weaponized RMM hunting guide citing a 277% year-over-year rise in RMM abuse and listing MuddyWater, Hive, Storm-1811 and RansomHub use
  • End of ANY.RUN's observation window; 94% of 240 hosts were seen on only one day, indicating rapid infrastructure rotation
  • ANY.RUN publishes research on RMM phishing spanning 46 countries with tax, Social Security, Adobe, invoice, shipping and DocuSign lures
  • AhnLab ASEC publishes analysis of six legitimate RMM tools (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able) distributed via phishing, with IOCs

Sources cited for RMM tools distributed via phishing

Detection coverage for TL-2026-3037

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3037 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats